Stack-based Buffer Overflow Vulnerability in Deco M9 Plus by TP-Link
CVE-2026-8618

7.7HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-8618?

A vulnerability exists in the TDDPv2 service on the Deco M9 Plus due to inadequate validation of the length of decrypted request data. This flaw can lead to a stack-based buffer overflow in the subtype 0x91 handler, making it possible for an adjacent unauthenticated attacker to exploit during the device setup phase by sending maliciously crafted TDDP packets. Exploitation could result in a denial of service or arbitrary code execution, posing significant security risks to the affected devices.

Affected Version(s)

Deco M9 Plus V2 0 < 1.9.2 Build 20260818

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Isa Roovers
.